17:24:52.0613 1120 ose - ok
17:24:52.0660 1120 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:24:52.0675 1120 p2pimsvc - ok
17:24:52.0691 1120 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:24:52.0707 1120 p2psvc - ok
17:24:52.0738 1120 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:24:52.0738 1120 Parport - ok
17:24:52.0785 1120 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:24:52.0785 1120 partmgr - ok
17:24:52.0800 1120 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:24:52.0816 1120 Parvdm - ok
17:24:52.0910 1120 [ 3CAE2BBC86FCF7F94C9696994AF30386 ] PassThru Service C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
17:24:52.0910 1120 PassThru Service - ok
17:24:52.0957 1120 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:24:52.0957 1120 PcaSvc - ok
17:24:52.0988 1120 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:24:52.0988 1120 pci - ok
17:24:53.0035 1120 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:24:53.0035 1120 pciide - ok
17:24:53.0066 1120 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:24:53.0066 1120 pcmcia - ok
17:24:53.0097 1120 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:24:53.0097 1120 pcw - ok
17:24:53.0222 1120 [ 20372BE109FEE1C37E2D5216680DB9EB ] PDF Architect Helper Service C:\Program Files\PDF Architect\HelperService.exe
17:24:53.0222 1120 PDF Architect Helper Service - ok
17:24:53.0269 1120 [ B90A279073A815A4AA2C45A09EE004FA ] PDF Architect Service C:\Program Files\PDF Architect\ConversionService.exe
17:24:53.0285 1120 PDF Architect Service - ok
17:24:53.0332 1120 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:24:53.0332 1120 PEAUTH - ok
17:24:53.0378 1120 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:24:53.0410 1120 PeerDistSvc - ok
17:24:53.0472 1120 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:24:53.0519 1120 pla - ok
17:24:53.0597 1120 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:24:53.0613 1120 PlugPlay - ok
17:24:53.0628 1120 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:24:53.0628 1120 PNRPAutoReg - ok
17:24:53.0644 1120 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:24:53.0660 1120 PNRPsvc - ok
17:24:53.0691 1120 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:24:53.0707 1120 PolicyAgent - ok
17:24:53.0738 1120 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:24:53.0753 1120 Power - ok
17:24:53.0785 1120 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:24:53.0785 1120 PptpMiniport - ok
17:24:53.0785 1120 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys
17:24:53.0800 1120 Processor - ok
17:24:53.0863 1120 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:24:53.0863 1120 ProfSvc - ok
17:24:53.0878 1120 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:24:53.0878 1120 ProtectedStorage - ok
17:24:53.0910 1120 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:24:53.0910 1120 Psched - ok
17:24:53.0957 1120 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:24:53.0957 1120 ql2300 - ok
17:24:53.0988 1120 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:24:53.0988 1120 ql40xx - ok
17:24:54.0019 1120 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:24:54.0019 1120 QWAVE - ok
17:24:54.0035 1120 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:24:54.0035 1120 QWAVEdrv - ok
17:24:54.0097 1120 [ 8F97D374AD1857E1EED85A79F29A1D3D ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
17:24:54.0097 1120 RapiMgr - ok
17:24:54.0113 1120 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:24:54.0113 1120 RasAcd - ok
17:24:54.0160 1120 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:24:54.0160 1120 RasAgileVpn - ok
17:24:54.0191 1120 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:24:54.0191 1120 RasAuto - ok
17:24:54.0222 1120 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:24:54.0222 1120 Rasl2tp - ok
17:24:54.0238 1120 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:24:54.0253 1120 RasMan - ok
17:24:54.0269 1120 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:24:54.0269 1120 RasPppoe - ok
17:24:54.0300 1120 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:24:54.0300 1120 RasSstp - ok
17:24:54.0332 1120 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:24:54.0332 1120 rdbss - ok
17:24:54.0347 1120 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:24:54.0347 1120 rdpbus - ok
17:24:54.0363 1120 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:24:54.0378 1120 RDPCDD - ok
17:24:54.0410 1120 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:24:54.0410 1120 RDPDR - ok
17:24:54.0441 1120 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:24:54.0441 1120 RDPENCDD - ok
17:24:54.0472 1120 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:24:54.0488 1120 RDPREFMP - ok
17:24:54.0535 1120 [ 65375DF758CA1872AB7EBBBA457FD5E6 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:24:54.0535 1120 RdpVideoMiniport - ok
17:24:54.0597 1120 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:24:54.0597 1120 RDPWD - ok
17:24:54.0628 1120 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:24:54.0644 1120 rdyboost - ok
17:24:54.0675 1120 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:24:54.0675 1120 RemoteAccess - ok
17:24:54.0707 1120 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:24:54.0707 1120 RemoteRegistry - ok
17:24:54.0753 1120 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
17:24:54.0753 1120 RFCOMM - ok
17:24:54.0800 1120 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:24:54.0800 1120 RpcEptMapper - ok
17:24:54.0832 1120 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:24:54.0832 1120 RpcLocator - ok
17:24:54.0863 1120 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:24:54.0863 1120 RpcSs - ok
17:24:54.0910 1120 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:24:54.0910 1120 rspndr - ok
17:24:54.0941 1120 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:24:54.0941 1120 s3cap - ok
17:24:54.0957 1120 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
17:24:54.0957 1120 SamSs - ok
17:24:54.0988 1120 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:24:54.0988 1120 sbp2port - ok
17:24:55.0019 1120 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:24:55.0035 1120 SCardSvr - ok
17:24:55.0066 1120 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:24:55.0066 1120 scfilter - ok
17:24:55.0097 1120 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:24:55.0128 1120 Schedule - ok
17:24:55.0144 1120 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:24:55.0144 1120 SCPolicySvc - ok
17:24:55.0160 1120 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:24:55.0175 1120 SDRSVC - ok
17:24:55.0207 1120 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:24:55.0207 1120 secdrv - ok
17:24:55.0222 1120 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:24:55.0238 1120 seclogon - ok
17:24:55.0253 1120 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:24:55.0269 1120 SENS - ok
17:24:55.0285 1120 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:24:55.0300 1120 SensrSvc - ok
17:24:55.0316 1120 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:24:55.0316 1120 Serenum - ok
17:24:55.0332 1120 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:24:55.0332 1120 Serial - ok
17:24:55.0347 1120 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:24:55.0347 1120 sermouse - ok
17:24:55.0394 1120 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:24:55.0394 1120 SessionEnv - ok
17:24:55.0410 1120 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:24:55.0410 1120 sffdisk - ok
17:24:55.0425 1120 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:24:55.0425 1120 sffp_mmc - ok
17:24:55.0441 1120 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:24:55.0441 1120 sffp_sd - ok
17:24:55.0457 1120 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
17:24:55.0457 1120 sfloppy - ok
17:24:55.0488 1120 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:24:55.0503 1120 SharedAccess - ok
17:24:55.0519 1120 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:24:55.0535 1120 ShellHWDetection - ok
17:24:55.0550 1120 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:24:55.0550 1120 sisagp - ok
17:24:55.0582 1120 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
17:24:55.0582 1120 SiSRaid2 - ok
17:24:55.0597 1120 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:24:55.0597 1120 SiSRaid4 - ok
17:24:55.0675 1120 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:24:55.0691 1120 SkypeUpdate - ok
17:24:55.0722 1120 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:24:55.0722 1120 Smb - ok
17:24:55.0769 1120 [ 86D17B6760DD2B09E932FF101714E0DC ] smwdm C:\Windows\system32\drivers\smwdm.sys
17:24:55.0785 1120 smwdm - ok
17:24:55.0832 1120 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:24:55.0847 1120 SNMPTRAP - ok
17:24:55.0878 1120 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:24:55.0878 1120 spldr - ok
17:24:55.0941 1120 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:24:55.0957 1120 Spooler - ok
17:24:56.0050 1120 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:24:56.0082 1120 sppsvc - ok
17:24:56.0097 1120 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:24:56.0113 1120 sppuinotify - ok
17:24:56.0160 1120 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:24:56.0160 1120 srv - ok
17:24:56.0191 1120 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:24:56.0191 1120 srv2 - ok
17:24:56.0238 1120 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:24:56.0238 1120 srvnet - ok
17:24:56.0269 1120 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:24:56.0285 1120 SSDPSRV - ok
17:24:56.0347 1120 [ B9E31F2A3640403B0EA3A867BB73B9F4 ] SSHDRV86 C:\Windows\system32\drivers\SSHDRV86.sys
17:24:56.0363 1120 SSHDRV86 - ok
17:24:56.0363 1120 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:24:56.0378 1120 SstpSvc - ok
17:24:56.0410 1120 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys
17:24:56.0410 1120 stexstor - ok
17:24:56.0457 1120 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:24:56.0488 1120 StiSvc - ok
17:24:56.0503 1120 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:24:56.0503 1120 storflt - ok
17:24:56.0535 1120 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:24:56.0535 1120 storvsc - ok
17:24:56.0550 1120 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:24:56.0550 1120 swenum - ok
17:24:56.0582 1120 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:24:56.0597 1120 swprv - ok
17:24:56.0628 1120 [ F2AD8960812FD111E20E84659EF19D43 ] Synth3dVsc C:\Windows\system32\drivers\synth3dvsc.sys
17:24:56.0628 1120 Synth3dVsc - ok
17:24:56.0675 1120 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:24:56.0707 1120 SysMain - ok
17:24:56.0722 1120 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:24:56.0738 1120 TabletInputService - ok
17:24:56.0753 1120 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:24:56.0785 1120 TapiSrv - ok
17:24:56.0800 1120 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:24:56.0800 1120 TBS - ok
17:24:56.0894 1120 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:24:56.0894 1120 Tcpip - ok
17:24:56.0972 1120 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:24:56.0988 1120 TCPIP6 - ok
17:24:57.0035 1120 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:24:57.0035 1120 tcpipreg - ok
17:24:57.0082 1120 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:24:57.0082 1120 TDPIPE - ok
17:24:57.0113 1120 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:24:57.0113 1120 TDTCP - ok
17:24:57.0128 1120 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:24:57.0128 1120 tdx - ok
17:24:57.0144 1120 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:24:57.0144 1120 TermDD - ok
17:24:57.0191 1120 [ E951866BAC5A23403F62A349EDBB6EEB ] terminpt C:\Windows\system32\drivers\terminpt.sys
17:24:57.0191 1120 terminpt - ok
17:24:57.0238 1120 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:24:57.0253 1120 TermService - ok
17:24:57.0269 1120 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:24:57.0269 1120 Themes - ok
17:24:57.0285 1120 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:24:57.0285 1120 THREADORDER - ok
17:24:57.0332 1120 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:24:57.0332 1120 TrkWks - ok
17:24:57.0378 1120 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:24:57.0378 1120 TrustedInstaller - ok
17:24:57.0410 1120 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:24:57.0425 1120 tssecsrv - ok
17:24:57.0472 1120 [ 9CE253214ACAA5A7D323327D2055EFAA ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:24:57.0472 1120 TsUsbFlt - ok
17:24:57.0519 1120 [ 57C527AF84748B5C2F5178C499C0B81F ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
17:24:57.0519 1120 TsUsbGD - ok
17:24:57.0550 1120 [ 045ACB987C650D8186C6B4A692223860 ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys
17:24:57.0566 1120 tsusbhub - ok
17:24:57.0597 1120 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:24:57.0597 1120 tunnel - ok
17:24:57.0628 1120 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:24:57.0628 1120 uagp35 - ok
17:24:57.0644 1120 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:24:57.0644 1120 udfs - ok
17:24:57.0691 1120 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:24:57.0691 1120 UI0Detect - ok
17:24:57.0722 1120 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:24:57.0722 1120 uliagpkx - ok
17:24:57.0738 1120 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:24:57.0738 1120 umbus - ok
17:24:57.0753 1120 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys
17:24:57.0769 1120 UmPass - ok
17:24:57.0800 1120 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:24:57.0800 1120 UmRdpService - ok
17:24:57.0832 1120 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:24:57.0847 1120 upnphost - ok
17:24:57.0894 1120 [ 71D97F1A3CC47A56728F7A400A3F8295 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:24:57.0894 1120 usbccgp - ok
17:24:57.0941 1120 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:24:57.0941 1120 usbcir - ok
17:24:57.0988 1120 [ C4FB8E7ADEA9B5CEEA885A1B504B7E40 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:24:57.0988 1120 usbehci - ok
17:24:58.0050 1120 [ 86AA95ACB611001E26CD2C0145F2225A ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:24:58.0050 1120 usbhub - ok
17:24:58.0097 1120 [ DCDF9855145A14DFCA0AB32308871961 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:24:58.0097 1120 usbohci - ok
17:24:58.0128 1120 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:24:58.0128 1120 usbprint - ok
17:24:58.0175 1120 [ FC6B21DB4B5B398AB93DBE59CBF11036 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:24:58.0175 1120 usbscan - ok
17:24:58.0207 1120 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:24:58.0222 1120 USBSTOR - ok
17:24:58.0253 1120 [ 8E51D04175BAA14C4F79AA5F6D248770 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:24:58.0253 1120 usbuhci - ok
17:24:58.0285 1120 [ DE014425522610BEDCA3821BB8C0F1D5 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
17:24:58.0285 1120 usbvideo - ok
17:24:58.0363 1120 [ AF77716205C97E902E6C5B78DECE2CCA ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
17:24:58.0363 1120 usb_rndisx - ok
17:24:58.0394 1120 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:24:58.0394 1120 UxSms - ok
17:24:58.0410 1120 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
17:24:58.0410 1120 VaultSvc - ok
17:24:58.0441 1120 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:24:58.0457 1120 vdrvroot - ok
17:24:58.0472 1120 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:24:58.0488 1120 vds - ok
17:24:58.0519 1120 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:24:58.0519 1120 vga - ok
17:24:58.0535 1120 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:24:58.0535 1120 VgaSave - ok
17:24:58.0550 1120 VGPU - ok
17:24:58.0582 1120 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:24:58.0582 1120 vhdmp - ok
17:24:58.0597 1120 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:24:58.0597 1120 viaagp - ok
17:24:58.0613 1120 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:24:58.0628 1120 ViaC7 - ok
17:24:58.0675 1120 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:24:58.0675 1120 viaide - ok
17:24:58.0707 1120 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:24:58.0707 1120 vmbus - ok
17:24:58.0738 1120 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:24:58.0738 1120 VMBusHID - ok
17:24:58.0753 1120 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:24:58.0753 1120 volmgr - ok
17:24:58.0785 1120 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:24:58.0785 1120 volmgrx - ok
17:24:58.0800 1120 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:24:58.0800 1120 volsnap - ok
17:24:58.0832 1120 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:24:58.0832 1120 vsmraid - ok
17:24:58.0894 1120 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:24:58.0910 1120 VSS - ok
17:24:58.0941 1120 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:24:58.0941 1120 vwifibus - ok
17:24:58.0957 1120 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:24:58.0957 1120 W32Time - ok
17:24:59.0003 1120 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:24:59.0003 1120 WacomPen - ok
17:24:59.0035 1120 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:24:59.0050 1120 WANARP - ok
17:24:59.0066 1120 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:24:59.0066 1120 Wanarpv6 - ok
17:24:59.0144 1120 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:24:59.0191 1120 WatAdminSvc - ok
17:24:59.0253 1120 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:24:59.0285 1120 wbengine - ok
17:24:59.0300 1120 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:24:59.0300 1120 WbioSrvc - ok
17:24:59.0332 1120 [ 59E19BD13C3BDB857646B9E436BA27F7 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
17:24:59.0347 1120 WcesComm - ok
17:24:59.0363 1120 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:24:59.0363 1120 wcncsvc - ok
17:24:59.0378 1120 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:24:59.0394 1120 WcsPlugInService - ok
17:24:59.0410 1120 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys
17:24:59.0410 1120 Wd - ok
17:24:59.0472 1120 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:24:59.0472 1120 Wdf01000 - ok
17:24:59.0519 1120 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:24:59.0519 1120 WdiServiceHost - ok
17:24:59.0535 1120 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:24:59.0535 1120 WdiSystemHost - ok
17:24:59.0597 1120 [ 75E8EBD7040CE238684333F97014762A ] WebClient C:\Windows\System32\webclnt.dll
17:24:59.0597 1120 WebClient - ok
17:24:59.0628 1120 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:24:59.0660 1120 Wecsvc - ok
17:24:59.0675 1120 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:24:59.0675 1120 wercplsupport - ok
17:24:59.0707 1120 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:24:59.0707 1120 WerSvc - ok
17:24:59.0753 1120 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:24:59.0753 1120 WfpLwf - ok
17:24:59.0785 1120 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:24:59.0785 1120 WIMMount - ok
17:24:59.0878 1120 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:24:59.0878 1120 WinDefend - ok
17:24:59.0894 1120 WinHttpAutoProxySvc - ok
17:24:59.0957 1120 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:24:59.0957 1120 Winmgmt - ok
17:25:00.0066 1120 WinRing0_1_2_0 - ok
17:25:00.0113 1120 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:25:00.0160 1120 WinRM - ok
17:25:00.0238 1120 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:25:00.0238 1120 WinUsb - ok
17:25:00.0285 1120 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:25:00.0300 1120 Wlansvc - ok
17:25:00.0378 1120 [ 5E7C103F8475C4289847D15E129C20F7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:25:00.0394 1120 wlidsvc - ok
17:25:00.0425 1120 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
17:25:00.0425 1120 WmiAcpi - ok
17:25:00.0457 1120 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:25:00.0457 1120 wmiApSrv - ok
17:25:00.0535 1120 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:25:00.0550 1120 WMPNetworkSvc - ok
17:25:00.0582 1120 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:25:00.0597 1120 WPCSvc - ok
17:25:00.0613 1120 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:25:00.0613 1120 WPDBusEnum - ok
17:25:00.0644 1120 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:25:00.0660 1120 ws2ifsl - ok
17:25:00.0675 1120 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:25:00.0675 1120 wscsvc - ok
17:25:00.0691 1120 WSearch - ok
17:25:00.0769 1120 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:25:00.0800 1120 wuauserv - ok
17:25:00.0863 1120 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:25:00.0878 1120 WudfPf - ok
17:25:00.0957 1120 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:25:00.0957 1120 WUDFRd - ok
17:25:01.0082 1120 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:25:01.0082 1120 wudfsvc - ok
17:25:01.0144 1120 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:25:01.0160 1120 WwanSvc - ok
17:25:01.0207 1120 ================ Scan global ===============================
17:25:01.0238 1120 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:25:01.0285 1120 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:25:01.0300 1120 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:25:01.0316 1120 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:25:01.0347 1120 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:25:01.0347 1120 [Global] - ok
17:25:01.0347 1120 ================ Scan MBR ==================================
17:25:01.0363 1120 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:25:01.0785 1120 \Device\Harddisk0\DR0 - ok
17:25:01.0800 1120 [ D1AD4C53EADD115593E05FA56D6B9DEA ] \Device\Harddisk1\DR1
17:25:02.0332 1120 \Device\Harddisk1\DR1 - ok
17:25:02.0332 1120 ================ Scan VBR ==================================
17:25:02.0332 1120 [ 08931B07838BF5B3ABA113909F7617F8 ] \Device\Harddisk0\DR0\Partition1
17:25:02.0332 1120 \Device\Harddisk0\DR0\Partition1 - ok
17:25:02.0332 1120 [ A441D5B79C5F2E697E40E9A36BC4B183 ] \Device\Harddisk1\DR1\Partition1
17:25:02.0347 1120 \Device\Harddisk1\DR1\Partition1 - ok
17:25:02.0347 1120 ============================================================
17:25:02.0347 1120 Scan finished
17:25:02.0347 1120 ============================================================
17:25:02.0363 4648 Detected object count: 0
17:25:02.0363 4648 Actual detected object count: 0
17:25:11.0738 4160 Deinitialize success
Kontrola logu Hjt Vyřešeno
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu Hjt
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Kontrola logu Hjt
ComboFix 13-11-04.01 - Miroslav 06.11.2013 1:33.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1162 [GMT 1:00]
Spuštěný z: c:\users\Miroslav\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\UNWISE.EXE
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-06 do 2013-11-06 )))))))))))))))))))))))))))))))
.
.
2013-11-06 00:45 . 2013-11-06 00:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-05 16:16 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8862341-1F56-4FA6-B193-B9B547C33660}\mpengine.dll
2013-11-04 15:56 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-04 15:51 . 2013-11-04 15:51 -------- d-----w- c:\windows\ERUNT
2013-11-03 18:40 . 2013-11-03 18:40 -------- d-----w- c:\users\Miroslav\AppData\Local\Adobe
2013-11-03 18:10 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2013-11-03 18:10 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2013-11-03 18:10 . 2009-03-09 14:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2013-11-03 18:10 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2013-11-03 18:10 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2013-11-03 17:55 . 2013-11-03 18:15 -------- d-----w- c:\program files\SIMT
2013-11-03 17:40 . 2013-11-03 17:40 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Open Rails
2013-11-03 15:37 . 2013-11-04 16:05 -------- d-----w- C:\AdwCleaner
2013-11-03 14:19 . 2013-11-03 14:19 -------- d-----w- c:\users\Miroslav\AppData\Local\ATI
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Malwarebytes
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Local\Apps
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-03 13:55 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Zoner
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Local\Zoner
2013-10-26 13:14 . 2013-10-26 13:14 -------- d-----w- c:\program files\Zoner
2013-10-26 13:10 . 2013-10-26 13:10 -------- d-----w- c:\programdata\Zoner
2013-10-26 12:46 . 2013-10-26 12:46 -------- d-----w- c:\users\Miroslav\AppData\Local\IsolatedStorage
2013-10-26 12:45 . 2013-10-26 12:45 -------- d-----w- c:\program files\Microsoft
2013-10-26 12:23 . 2013-10-26 12:23 -------- d-----w- c:\program files\MSECache
2013-10-23 16:10 . 2013-10-23 16:10 917504 ----a-w- c:\windows\system32\FLASH.OCX
2013-10-23 16:10 . 2013-10-23 16:10 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-10-23 14:56 . 2013-10-23 14:56 81408 ----a-w- c:\windows\system32\drivers\SSHDRV86.sys
2013-10-20 15:32 . 2013-10-20 15:31 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3696C68-9339-4C15-B462-4E4D8E295649}\gapaengine.dll
2013-10-14 01:35 . 2013-10-14 01:35 -------- d-----w- c:\users\Default\AppData\Local\Google
2013-10-10 15:49 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-10 15:49 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-10 15:49 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-10 15:49 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-10 15:49 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-10 15:49 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-10 15:49 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-10 15:06 . 2013-10-10 15:06 -------- d-----w- c:\windows\TempF85A0999-886C-0FAD-3325-B952EB0A1238-Signatures
2013-10-10 14:51 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 14:51 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 14:51 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 14:51 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 14:51 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 14:51 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 14:51 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 14:51 . 2013-07-12 10:08 146816 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-10-10 14:51 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 14:49 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-16 01:44 . 2013-05-10 02:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-16 01:44 . 2013-05-09 20:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 20:08 . 2013-09-18 20:08 94208 ----a-w- c:\windows\system32\dpl100.dll
2013-09-06 19:20 . 2013-05-21 12:46 718712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-09-05 15:42 . 2013-09-05 15:42 4608 ----a-w- c:\windows\system32\w95inf32.dll
2013-09-05 15:42 . 2013-09-05 15:42 2272 ----a-w- c:\windows\system32\w95inf16.dll
2013-08-26 09:13 . 2013-08-26 09:13 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE" [2013-05-09 249440]
"SkyDrive"="c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
"Hlídač"="c:\program files\Energie pod palcem\Hlidac.exe" [2005-04-04 569856]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE" [2013-10-18 801816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 995184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-24 642304]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-08-21 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
start AMD Accelerated Video Transcoding device initialization [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-10-11 19:56 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2013-08-21 09:19 450560 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-08-29 00:23 1861968 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-06-15 07:50 138096 ----atw- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2013-05-13 08:19 659456 ----a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-11-01 02:38 29919576 ----a-w- c:\users\Miroslav\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Quick Moto Agent]
2004-03-21 13:43 459776 ----a-w- c:\program files\Quick Moto\Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-09-30 10:19 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R3 AVEO;USB2.0 PC Camera;c:\windows\system32\DRIVERS\AVEOdcnt.sys [2010-09-06 239104]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-07-18 295376]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-05-11 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp [x]
S1 gwiopm;gwiopm;c:\windows\system32\drivers\gwiopm.sys [1998-06-03 3904]
S1 SSHDRV86;SSHDRV86;c:\windows\system32\drivers\SSHDRV86.sys [2013-10-23 81408]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2013-05-09 142432]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2010-07-28 97792]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [2013-04-08 1320496]
S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [2013-04-08 799280]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-10 01:44]
.
2013-07-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000Core.job
- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-15 07:50]
.
2013-07-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000UA.job
- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-15 07:50]
.
2013-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-05 16:04]
.
2013-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-05 16:04]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\vh1ihku5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-ABBYY Screenshot Reader Bonus - (no file)
HKCU-Run-Zoner Photo Studio Service 16 - c:\program files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEc:\program files\Zoner\Photo Studio 16\Program32\ZPSService.exe
HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-IECT3288691 - c:\programdata\Conduit\IE\CT3288691\UninstallerUI.exe
AddRemove-DSite - c:\users\Miroslav\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRing0_1_2_0]
"ImagePath"="\??\c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-11-06 01:48:04
ComboFix-quarantined-files.txt 2013-11-06 00:48
.
Před spuštěním: Volných bajtů: 16 108 199 936
Po spuštění: Volných bajtů: 15 791 837 184
.
- - End Of File - - D422DA3292F31FA8550181A033DEA798
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1162 [GMT 1:00]
Spuštěný z: c:\users\Miroslav\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\UNWISE.EXE
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-06 do 2013-11-06 )))))))))))))))))))))))))))))))
.
.
2013-11-06 00:45 . 2013-11-06 00:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-05 16:16 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8862341-1F56-4FA6-B193-B9B547C33660}\mpengine.dll
2013-11-04 15:56 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-04 15:51 . 2013-11-04 15:51 -------- d-----w- c:\windows\ERUNT
2013-11-03 18:40 . 2013-11-03 18:40 -------- d-----w- c:\users\Miroslav\AppData\Local\Adobe
2013-11-03 18:10 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2013-11-03 18:10 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2013-11-03 18:10 . 2009-03-09 14:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2013-11-03 18:10 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2013-11-03 18:10 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2013-11-03 17:55 . 2013-11-03 18:15 -------- d-----w- c:\program files\SIMT
2013-11-03 17:40 . 2013-11-03 17:40 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Open Rails
2013-11-03 15:37 . 2013-11-04 16:05 -------- d-----w- C:\AdwCleaner
2013-11-03 14:19 . 2013-11-03 14:19 -------- d-----w- c:\users\Miroslav\AppData\Local\ATI
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Malwarebytes
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Local\Apps
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-03 13:55 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Zoner
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Local\Zoner
2013-10-26 13:14 . 2013-10-26 13:14 -------- d-----w- c:\program files\Zoner
2013-10-26 13:10 . 2013-10-26 13:10 -------- d-----w- c:\programdata\Zoner
2013-10-26 12:46 . 2013-10-26 12:46 -------- d-----w- c:\users\Miroslav\AppData\Local\IsolatedStorage
2013-10-26 12:45 . 2013-10-26 12:45 -------- d-----w- c:\program files\Microsoft
2013-10-26 12:23 . 2013-10-26 12:23 -------- d-----w- c:\program files\MSECache
2013-10-23 16:10 . 2013-10-23 16:10 917504 ----a-w- c:\windows\system32\FLASH.OCX
2013-10-23 16:10 . 2013-10-23 16:10 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-10-23 14:56 . 2013-10-23 14:56 81408 ----a-w- c:\windows\system32\drivers\SSHDRV86.sys
2013-10-20 15:32 . 2013-10-20 15:31 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3696C68-9339-4C15-B462-4E4D8E295649}\gapaengine.dll
2013-10-14 01:35 . 2013-10-14 01:35 -------- d-----w- c:\users\Default\AppData\Local\Google
2013-10-10 15:49 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-10 15:49 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-10 15:49 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-10 15:49 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-10 15:49 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-10 15:49 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-10 15:49 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-10 15:06 . 2013-10-10 15:06 -------- d-----w- c:\windows\TempF85A0999-886C-0FAD-3325-B952EB0A1238-Signatures
2013-10-10 14:51 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 14:51 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 14:51 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 14:51 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 14:51 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 14:51 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 14:51 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 14:51 . 2013-07-12 10:08 146816 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-10-10 14:51 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 14:49 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-16 01:44 . 2013-05-10 02:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-16 01:44 . 2013-05-09 20:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 20:08 . 2013-09-18 20:08 94208 ----a-w- c:\windows\system32\dpl100.dll
2013-09-06 19:20 . 2013-05-21 12:46 718712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-09-05 15:42 . 2013-09-05 15:42 4608 ----a-w- c:\windows\system32\w95inf32.dll
2013-09-05 15:42 . 2013-09-05 15:42 2272 ----a-w- c:\windows\system32\w95inf16.dll
2013-08-26 09:13 . 2013-08-26 09:13 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE" [2013-05-09 249440]
"SkyDrive"="c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
"Hlídač"="c:\program files\Energie pod palcem\Hlidac.exe" [2005-04-04 569856]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE" [2013-10-18 801816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 995184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-24 642304]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-08-21 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
start AMD Accelerated Video Transcoding device initialization [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-10-11 19:56 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2013-08-21 09:19 450560 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-08-29 00:23 1861968 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-06-15 07:50 138096 ----atw- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2013-05-13 08:19 659456 ----a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-11-01 02:38 29919576 ----a-w- c:\users\Miroslav\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Quick Moto Agent]
2004-03-21 13:43 459776 ----a-w- c:\program files\Quick Moto\Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-09-30 10:19 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R3 AVEO;USB2.0 PC Camera;c:\windows\system32\DRIVERS\AVEOdcnt.sys [2010-09-06 239104]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-07-18 295376]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-05-11 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp [x]
S1 gwiopm;gwiopm;c:\windows\system32\drivers\gwiopm.sys [1998-06-03 3904]
S1 SSHDRV86;SSHDRV86;c:\windows\system32\drivers\SSHDRV86.sys [2013-10-23 81408]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2013-05-09 142432]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2010-07-28 97792]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [2013-04-08 1320496]
S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [2013-04-08 799280]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-10 01:44]
.
2013-07-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000Core.job
- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-15 07:50]
.
2013-07-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000UA.job
- c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-15 07:50]
.
2013-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-05 16:04]
.
2013-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-05 16:04]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\vh1ihku5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-ABBYY Screenshot Reader Bonus - (no file)
HKCU-Run-Zoner Photo Studio Service 16 - c:\program files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEc:\program files\Zoner\Photo Studio 16\Program32\ZPSService.exe
HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-IECT3288691 - c:\programdata\Conduit\IE\CT3288691\UninstallerUI.exe
AddRemove-DSite - c:\users\Miroslav\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRing0_1_2_0]
"ImagePath"="\??\c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-11-06 01:48:04
ComboFix-quarantined-files.txt 2013-11-06 00:48
.
Před spuštěním: Volných bajtů: 16 108 199 936
Po spuštění: Volných bajtů: 15 791 837 184
.
- - End Of File - - D422DA3292F31FA8550181A033DEA798
A36C5E4F47E84449FF07ED3517B43A31
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43339
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu Hjt
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\users\Miroslav\AppData\Local\Facebook\Update
c:\program files\Skype\Updater
c:\program files\Google\Update
Driver::
SkypeUpdate
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Kontrola logu Hjt
ComboFix 13-11-04.01 - Miroslav 06.11.2013 17:11:05.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1395 [GMT 1:00]
Spuštěný z: c:\users\Miroslav\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Miroslav\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.165\goopdate.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.165\psmachine.dll
c:\program files\Google\Update\1.3.21.165\psuser.dll
c:\program files\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\0.0.0.0\gsync.msi
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\users\Miroslav\AppData\Local\Facebook\Update
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookCrashHandler.exe
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdate.exe
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdateHelper.msi
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ar.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bg.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bn.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ca.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_cs.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_da.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_de.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_el.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en-GB.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es-419.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_et.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fa.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fil.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_gu.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hu.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_id.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_is.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_it.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_iw.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ja.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_kn.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ko.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lt.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lv.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ml.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_mr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ms.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_nl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_no.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_or.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-BR.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-PT.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ro.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ru.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sk.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sv.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ta.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_te.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_th.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_tr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_uk.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ur.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_vi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-CN.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-TW.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-06 do 2013-11-06 )))))))))))))))))))))))))))))))
.
.
2013-11-06 16:21 . 2013-11-06 16:23 -------- d-----w- c:\users\Miroslav\AppData\Local\temp
2013-11-06 16:21 . 2013-11-06 16:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-06 15:12 . 2013-11-06 15:12 -------- d-----w- c:\users\Miroslav\AppData\Local\Apple
2013-11-05 16:16 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8862341-1F56-4FA6-B193-B9B547C33660}\mpengine.dll
2013-11-04 15:56 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-04 15:51 . 2013-11-04 15:51 -------- d-----w- c:\windows\ERUNT
2013-11-03 18:40 . 2013-11-03 18:40 -------- d-----w- c:\users\Miroslav\AppData\Local\Adobe
2013-11-03 18:10 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2013-11-03 18:10 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2013-11-03 18:10 . 2009-03-09 14:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2013-11-03 18:10 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2013-11-03 18:10 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2013-11-03 17:55 . 2013-11-03 18:15 -------- d-----w- c:\program files\SIMT
2013-11-03 17:40 . 2013-11-03 17:40 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Open Rails
2013-11-03 15:37 . 2013-11-04 16:05 -------- d-----w- C:\AdwCleaner
2013-11-03 14:19 . 2013-11-03 14:19 -------- d-----w- c:\users\Miroslav\AppData\Local\ATI
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Malwarebytes
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Local\Apps
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-03 13:55 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Zoner
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Local\Zoner
2013-10-26 13:14 . 2013-10-26 13:14 -------- d-----w- c:\program files\Zoner
2013-10-26 13:10 . 2013-10-26 13:10 -------- d-----w- c:\programdata\Zoner
2013-10-26 12:46 . 2013-10-26 12:46 -------- d-----w- c:\users\Miroslav\AppData\Local\IsolatedStorage
2013-10-26 12:45 . 2013-10-26 12:45 -------- d-----w- c:\program files\Microsoft
2013-10-26 12:23 . 2013-10-26 12:23 -------- d-----w- c:\program files\MSECache
2013-10-23 16:10 . 2013-10-23 16:10 917504 ----a-w- c:\windows\system32\FLASH.OCX
2013-10-23 16:10 . 2013-10-23 16:10 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-10-23 14:56 . 2013-10-23 14:56 81408 ----a-w- c:\windows\system32\drivers\SSHDRV86.sys
2013-10-20 15:32 . 2013-10-20 15:31 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3696C68-9339-4C15-B462-4E4D8E295649}\gapaengine.dll
2013-10-14 01:35 . 2013-10-14 01:35 -------- d-----w- c:\users\Default\AppData\Local\Google
2013-10-10 15:49 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-10 15:49 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-10 15:49 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-10 15:49 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-10 15:49 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-10 15:49 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-10 15:49 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-10 15:06 . 2013-10-10 15:06 -------- d-----w- c:\windows\TempF85A0999-886C-0FAD-3325-B952EB0A1238-Signatures
2013-10-10 14:51 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 14:51 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 14:51 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 14:51 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 14:51 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 14:51 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 14:51 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 14:51 . 2013-07-12 10:08 146816 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-10-10 14:51 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 14:49 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-16 01:44 . 2013-05-10 02:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-16 01:44 . 2013-05-09 20:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 20:08 . 2013-09-18 20:08 94208 ----a-w- c:\windows\system32\dpl100.dll
2013-09-06 19:20 . 2013-05-21 12:46 718712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-09-05 15:42 . 2013-09-05 15:42 4608 ----a-w- c:\windows\system32\w95inf32.dll
2013-09-05 15:42 . 2013-09-05 15:42 2272 ----a-w- c:\windows\system32\w95inf16.dll
2013-08-26 09:13 . 2013-08-26 09:13 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE" [2013-05-09 249440]
"SkyDrive"="c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
"Hlídač"="c:\program files\Energie pod palcem\Hlidac.exe" [2005-04-04 569856]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE" [2013-10-18 801816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 995184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-24 642304]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-08-21 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
start AMD Accelerated Video Transcoding device initialization [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-10-11 19:56 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2013-08-21 09:19 450560 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-08-29 00:23 1861968 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2013-05-13 08:19 659456 ----a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-11-01 02:38 29919576 ----a-w- c:\users\Miroslav\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Quick Moto Agent]
2004-03-21 13:43 459776 ----a-w- c:\program files\Quick Moto\Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-09-30 10:19 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R3 AVEO;USB2.0 PC Camera;c:\windows\system32\DRIVERS\AVEOdcnt.sys [2010-09-06 239104]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-07-18 295376]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-05-11 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp [x]
S1 gwiopm;gwiopm;c:\windows\system32\drivers\gwiopm.sys [1998-06-03 3904]
S1 SSHDRV86;SSHDRV86;c:\windows\system32\drivers\SSHDRV86.sys [2013-10-23 81408]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2013-05-09 142432]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2010-07-28 97792]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [2013-04-08 1320496]
S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [2013-04-08 799280]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-10 01:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\vh1ihku5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRing0_1_2_0]
"ImagePath"="\??\c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\dinotify.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-11-06 17:27:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-06 16:27
ComboFix2.txt 2013-11-06 00:48
.
Před spuštěním: Volných bajtů: 17 560 694 784
Po spuštění: Volných bajtů: 17 364 443 136
.
- - End Of File - - BF46D84F597E8F2CF7BE4912DCD706A1
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1395 [GMT 1:00]
Spuštěný z: c:\users\Miroslav\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Miroslav\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3688081923-1990370972-2290267237-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.165\goopdate.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.165\psmachine.dll
c:\program files\Google\Update\1.3.21.165\psuser.dll
c:\program files\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\0.0.0.0\gsync.msi
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\users\Miroslav\AppData\Local\Facebook\Update
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookCrashHandler.exe
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdate.exe
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdateHelper.msi
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ar.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bg.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bn.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ca.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_cs.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_da.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_de.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_el.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en-GB.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es-419.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_et.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fa.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fil.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_gu.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hu.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_id.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_is.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_it.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_iw.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ja.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_kn.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ko.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lt.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lv.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ml.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_mr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ms.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_nl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_no.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_or.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-BR.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-PT.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ro.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ru.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sk.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sl.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sv.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ta.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_te.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_th.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_tr.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_uk.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ur.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_vi.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-CN.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-TW.dll
c:\users\Miroslav\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-06 do 2013-11-06 )))))))))))))))))))))))))))))))
.
.
2013-11-06 16:21 . 2013-11-06 16:23 -------- d-----w- c:\users\Miroslav\AppData\Local\temp
2013-11-06 16:21 . 2013-11-06 16:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-06 15:12 . 2013-11-06 15:12 -------- d-----w- c:\users\Miroslav\AppData\Local\Apple
2013-11-05 16:16 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8862341-1F56-4FA6-B193-B9B547C33660}\mpengine.dll
2013-11-04 15:56 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-04 15:51 . 2013-11-04 15:51 -------- d-----w- c:\windows\ERUNT
2013-11-03 18:40 . 2013-11-03 18:40 -------- d-----w- c:\users\Miroslav\AppData\Local\Adobe
2013-11-03 18:10 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2013-11-03 18:10 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2013-11-03 18:10 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2013-11-03 18:10 . 2009-03-09 14:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2013-11-03 18:10 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2013-11-03 18:10 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2013-11-03 17:55 . 2013-11-03 18:15 -------- d-----w- c:\program files\SIMT
2013-11-03 17:40 . 2013-11-03 17:40 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Open Rails
2013-11-03 15:37 . 2013-11-04 16:05 -------- d-----w- C:\AdwCleaner
2013-11-03 14:19 . 2013-11-03 14:19 -------- d-----w- c:\users\Miroslav\AppData\Local\ATI
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Malwarebytes
2013-11-03 13:56 . 2013-11-03 13:56 -------- d-----w- c:\users\Miroslav\AppData\Local\Apps
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-03 13:55 . 2013-11-03 13:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-03 13:55 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Roaming\Zoner
2013-10-26 13:15 . 2013-10-26 13:15 -------- d-----w- c:\users\Miroslav\AppData\Local\Zoner
2013-10-26 13:14 . 2013-10-26 13:14 -------- d-----w- c:\program files\Zoner
2013-10-26 13:10 . 2013-10-26 13:10 -------- d-----w- c:\programdata\Zoner
2013-10-26 12:46 . 2013-10-26 12:46 -------- d-----w- c:\users\Miroslav\AppData\Local\IsolatedStorage
2013-10-26 12:45 . 2013-10-26 12:45 -------- d-----w- c:\program files\Microsoft
2013-10-26 12:23 . 2013-10-26 12:23 -------- d-----w- c:\program files\MSECache
2013-10-23 16:10 . 2013-10-23 16:10 917504 ----a-w- c:\windows\system32\FLASH.OCX
2013-10-23 16:10 . 2013-10-23 16:10 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-10-23 14:56 . 2013-10-23 14:56 81408 ----a-w- c:\windows\system32\drivers\SSHDRV86.sys
2013-10-20 15:32 . 2013-10-20 15:31 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3696C68-9339-4C15-B462-4E4D8E295649}\gapaengine.dll
2013-10-14 01:35 . 2013-10-14 01:35 -------- d-----w- c:\users\Default\AppData\Local\Google
2013-10-10 15:49 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-10 15:49 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-10 15:49 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-10 15:49 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-10 15:49 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-10 15:49 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-10 15:49 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-10 15:06 . 2013-10-10 15:06 -------- d-----w- c:\windows\TempF85A0999-886C-0FAD-3325-B952EB0A1238-Signatures
2013-10-10 14:51 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 14:51 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 14:51 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 14:51 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 14:51 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 14:51 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 14:51 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 14:51 . 2013-07-12 10:08 146816 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-10-10 14:51 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 14:49 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-16 01:44 . 2013-05-10 02:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-16 01:44 . 2013-05-09 20:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 20:08 . 2013-09-18 20:08 94208 ----a-w- c:\windows\system32\dpl100.dll
2013-09-06 19:20 . 2013-05-21 12:46 718712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-09-05 15:42 . 2013-09-05 15:42 4608 ----a-w- c:\windows\system32\w95inf32.dll
2013-09-05 15:42 . 2013-09-05 15:42 2272 ----a-w- c:\windows\system32\w95inf16.dll
2013-08-26 09:13 . 2013-08-26 09:13 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 19:59 222832 ----a-w- c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE" [2013-05-09 249440]
"SkyDrive"="c:\users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
"Hlídač"="c:\program files\Energie pod palcem\Hlidac.exe" [2005-04-04 569856]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE" [2013-10-18 801816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 995184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-24 642304]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-08-21 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
start AMD Accelerated Video Transcoding device initialization [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-10-11 19:56 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2013-08-21 09:19 450560 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-08-29 00:23 1861968 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2013-05-13 08:19 659456 ----a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-11-01 02:38 29919576 ----a-w- c:\users\Miroslav\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Quick Moto Agent]
2004-03-21 13:43 459776 ----a-w- c:\program files\Quick Moto\Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-09-30 10:19 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R3 AVEO;USB2.0 PC Camera;c:\windows\system32\DRIVERS\AVEOdcnt.sys [2010-09-06 239104]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-07-18 295376]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-05-11 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp [x]
S1 gwiopm;gwiopm;c:\windows\system32\drivers\gwiopm.sys [1998-06-03 3904]
S1 SSHDRV86;SSHDRV86;c:\windows\system32\drivers\SSHDRV86.sys [2013-10-23 81408]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2013-05-09 142432]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2010-07-28 97792]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [2013-04-08 1320496]
S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [2013-04-08 799280]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-10 01:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Miroslav\AppData\Roaming\Mozilla\Firefox\Profiles\vh1ihku5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRing0_1_2_0]
"ImagePath"="\??\c:\users\Miroslav\AppData\Local\Temp\tmp77B4.tmp"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\dinotify.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-11-06 17:27:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-06 16:27
ComboFix2.txt 2013-11-06 00:48
.
Před spuštěním: Volných bajtů: 17 560 694 784
Po spuštění: Volných bajtů: 17 364 443 136
.
- - End Of File - - BF46D84F597E8F2CF7BE4912DCD706A1
A36C5E4F47E84449FF07ED3517B43A31
Re: Kontrola logu Hjt
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-11-06 17:34:08
-----------------------------
17:34:08.942 OS Version: Windows 6.1.7601 Service Pack 1
17:34:08.942 Number of processors: 2 586 0x403
17:34:08.942 ComputerName: MIROSLAV-PC UserName: Miroslav
17:34:09.473 Initialize success
17:34:39.352 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
17:34:39.352 Disk 0 Vendor: ST380815AS 4.AAB Size: 76319MB BusType: 3
17:34:39.352 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-5
17:34:39.352 Disk 1 Vendor: ST380815AS 3.AAC Size: 76319MB BusType: 3
17:34:39.477 Disk 0 MBR read successfully
17:34:39.477 Disk 0 MBR scan
17:34:39.493 Disk 0 Windows 7 default MBR code
17:34:39.493 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76316 MB offset 63
17:34:39.493 Disk 0 scanning sectors +156296704
17:34:39.586 Disk 0 scanning C:\Windows\system32\drivers
17:34:49.165 Service scanning
17:35:07.961 Modules scanning
17:35:19.758 Disk 0 trace - called modules:
17:35:19.774 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
17:35:20.290 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e74648]
17:35:20.290 3 CLASSPNP.SYS[8a28159e] -> nt!IofCallDriver -> [0x85d8d918]
17:35:20.305 5 ACPI.sys[89a443d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85d95908]
17:35:20.305 Scan finished successfully
17:35:40.540 Disk 0 MBR has been saved successfully to "C:\Users\Miroslav\Desktop\MBR.dat"
17:35:40.555 The log file has been saved successfully to "C:\Users\Miroslav\Desktop\aswMBR.txt"
Run date: 2013-11-06 17:34:08
-----------------------------
17:34:08.942 OS Version: Windows 6.1.7601 Service Pack 1
17:34:08.942 Number of processors: 2 586 0x403
17:34:08.942 ComputerName: MIROSLAV-PC UserName: Miroslav
17:34:09.473 Initialize success
17:34:39.352 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
17:34:39.352 Disk 0 Vendor: ST380815AS 4.AAB Size: 76319MB BusType: 3
17:34:39.352 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-5
17:34:39.352 Disk 1 Vendor: ST380815AS 3.AAC Size: 76319MB BusType: 3
17:34:39.477 Disk 0 MBR read successfully
17:34:39.477 Disk 0 MBR scan
17:34:39.493 Disk 0 Windows 7 default MBR code
17:34:39.493 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76316 MB offset 63
17:34:39.493 Disk 0 scanning sectors +156296704
17:34:39.586 Disk 0 scanning C:\Windows\system32\drivers
17:34:49.165 Service scanning
17:35:07.961 Modules scanning
17:35:19.758 Disk 0 trace - called modules:
17:35:19.774 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
17:35:20.290 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e74648]
17:35:20.290 3 CLASSPNP.SYS[8a28159e] -> nt!IofCallDriver -> [0x85d8d918]
17:35:20.305 5 ACPI.sys[89a443d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85d95908]
17:35:20.305 Scan finished successfully
17:35:40.540 Disk 0 MBR has been saved successfully to "C:\Users\Miroslav\Desktop\MBR.dat"
17:35:40.555 The log file has been saved successfully to "C:\Users\Miroslav\Desktop\aswMBR.txt"
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu Hjt
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC na plochu, spusť jej a klikni na Clean up!
+ Nový log z HJT
Jak se chová PC?
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC na plochu, spusť jej a klikni na Clean up!
+ Nový log z HJT
Jak se chová PC?
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Kontrola logu Hjt
Vypada,ze uz normalne.Ptvirala se nejaka stranka sama v Mozzile a ted to uz nedela
Re: Kontrola logu Hjt
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:03:22, on 7.11.2013
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHKE.EXE
C:\Users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files\Energie pod palcem\Hlidac.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Opera\Opera.exe
C:\Users\Miroslav\Desktop\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX230"
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Hlídač] C:\Program Files\Energie pod palcem\Hlidac.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Miroslav\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Miroslav\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files\PDF Architect\ConversionService.exe
--
End of file - 7613 bytes
Scan saved at 0:03:22, on 7.11.2013
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHKE.EXE
C:\Users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files\Energie pod palcem\Hlidac.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Opera\Opera.exe
C:\Users\Miroslav\Desktop\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX230"
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Miroslav\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Hlídač] C:\Program Files\Energie pod palcem\Hlidac.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Miroslav\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Miroslav\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files\PDF Architect\ConversionService.exe
--
End of file - 7613 bytes
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43339
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola logu Hjt Vyřešeno
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Návod
Kód: Vybrat vše
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 15 hostů